ExitProof
REMOTE · EXITPROOF.DAVISVILLELABS.COM · SCANNED SEP 28
Reversibility intelligence and durable exit evidence for AI agents before real-world commitments.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security69
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS enforcement could not be verified: the plaintext port answered with HTTP 405, which proves neither a plaintext path nor enforcement. View diagnostics → Unverified
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability65
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2042 tokens (~340/item across 6 items; 6 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management23
- Stability observed for 7 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 6 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 6 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the ExitProof MCP server?
ExitProof is a hosted endpoint at https://exitproof.davisvillelabs.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · exitproof.davisvillelabs.com
claude mcp add --transport http com-davisvillelabs-exitproof 'https://exitproof.davisvillelabs.com/mcp'
{
"mcpServers": {
"com-davisvillelabs-exitproof": {
"url": "https://exitproof.davisvillelabs.com/mcp"
}
}
} {
"servers": {
"com-davisvillelabs-exitproof": {
"type": "http",
"url": "https://exitproof.davisvillelabs.com/mcp"
}
}
} [mcp_servers.com-davisvillelabs-exitproof] url = "https://exitproof.davisvillelabs.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-davisvillelabs-exitproof": {
"type": "remote",
"url": "https://exitproof.davisvillelabs.com/mcp",
"enabled": true
}
}
} openclaw mcp add com-davisvillelabs-exitproof --url 'https://exitproof.davisvillelabs.com/mcp' --transport streamable-http
mcp_servers:
com-davisvillelabs-exitproof:
url: "https://exitproof.davisvillelabs.com/mcp" {
"McpServers": {
"com-davisvillelabs-exitproof": {
"Transport": "http",
"Url": "https://exitproof.davisvillelabs.com/mcp"
}
}
} assistant mcp add com-davisvillelabs-exitproof -t streamable-http -u 'https://exitproof.davisvillelabs.com/mcp'
{
"mcpServers": {
"com-davisvillelabs-exitproof": {
"type": "http",
"url": "https://exitproof.davisvillelabs.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 +3
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 26 Sept 26 0
- Tool “build_exit_pack” rewrote its description, which is the text the model reads security
- Tool “create_exit_manifest” rewrote its description, which is the text the model reads security
- Schema quality: 1599 → 2042 ▼ functional
- New tool “check_agent_purchase” functional
- 25 Sept 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 23 Sept 26 0
- Tool “build_exit_pack” rewrote its description, which is the text the model reads security
- Tool “check_reversibility” rewrote its description, which is the text the model reads security
- Tool “create_exit_manifest” rewrote its description, which is the text the model reads security
- Tool “get_exit_manifest” rewrote its description, which is the text the model reads security
- Tool “list_supported_policies” rewrote its description, which is the text the model reads security
- 22 Sept 26 +12
- Authorization: unverified → partial ▲ security
- Tool “build_exit_pack” rewrote its description, which is the text the model reads security
- Tool “check_reversibility” rewrote its description, which is the text the model reads security
- Tool “create_exit_manifest” rewrote its description, which is the text the model reads security
- Tool “get_exit_manifest” rewrote its description, which is the text the model reads security
- Tool “list_supported_policies” rewrote its description, which is the text the model reads security
- Schema quality: pass → fail ▼ functional
- Tool coverage: 8% → 100% ▲ functional
- Stability: unverified → 0.03 ▲ functional
- Tool “build_exit_pack” now declares an output schema ▲ functional
- Tool “check_reversibility” now declares an output schema ▲ functional
- Tool “create_exit_manifest” now declares an output schema ▲ functional
- Tool “get_exit_manifest” now declares an output schema ▲ functional
- Tool “list_supported_policies” now declares an output schema ▲ functional
- First check of Tool coverage: 100 functional
- Schema quality: fair → excellent functional
- “build_exit_pack” reworded the description of “access_token” cosmetic
- “build_exit_pack” reworded the description of “manifest_id” cosmetic
- “check_reversibility” reworded the description of “amount” cosmetic
- “check_reversibility” reworded the description of “checkout_terms” cosmetic
- “check_reversibility” reworded the description of “client_reference” cosmetic
- “check_reversibility” reworded the description of “commitment_type” cosmetic
- “check_reversibility” reworded the description of “country” cosmetic
- “check_reversibility” reworded the description of “currency” cosmetic
- “check_reversibility” reworded the description of “event_type” cosmetic
- “check_reversibility” reworded the description of “expected_commitment_at” cosmetic
- “check_reversibility” reworded the description of “merchant” cosmetic
- “check_reversibility” reworded the description of “purchase_channel” cosmetic
- “check_reversibility” reworded the description of “region” cosmetic
- “create_exit_manifest” reworded the description of “amount” cosmetic
- “create_exit_manifest” reworded the description of “checkout_terms” cosmetic
- “create_exit_manifest” reworded the description of “client_reference” cosmetic
- “create_exit_manifest” reworded the description of “commitment_type” cosmetic
- “create_exit_manifest” reworded the description of “country” cosmetic
- “create_exit_manifest” reworded the description of “currency” cosmetic
- “create_exit_manifest” reworded the description of “event_type” cosmetic
- “create_exit_manifest” reworded the description of “expected_commitment_at” cosmetic
- “create_exit_manifest” reworded the description of “merchant” cosmetic
- “create_exit_manifest” reworded the description of “purchase_channel” cosmetic
- “create_exit_manifest” reworded the description of “region” cosmetic
- “get_exit_manifest” reworded the description of “access_token” cosmetic
- “get_exit_manifest” reworded the description of “manifest_id” cosmetic
- 21 Sept 26 54
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 28 Sept 2026 · Probed https://exitproof.davisvillelabs.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=davisvillelabs.com | CN=WE1,O=Google Trust Services,C=US | 21 Sept 2026 | 20 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | 5262403e61f129c713c5d7155ae2ae1f |
| SANs: davisvillelabs.com, exitproof.davisvillelabs.com, *.exitproof.davisvillelabs.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of exitproof.davisvillelabs.com. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| davisvillelabs.com. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=(), payment=() |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://exitproof.davisvillelabs.com/mcp | Verified | 200 | |
| http (plaintext) | http://exitproof.davisvillelabs.com/mcp | Inconclusive | 405 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
build_exit_pack Build exit pack ~224
Build a bounded cancellation/refund action pack from an existing actionable Exit Manifest. Pass manifest_id and access_token together as the credential pair returned by create_exit_manifest or settlement recovery; use get_exit_manifest for retrieval only, or check_reversibility then create_exit_manifest when no manifest exists. This $1.00 MPP operation prefers Tempo stablecoin when available, retains Stripe card/link as a compatible fallback, and can charge but never contacts the merchant, executes a cancellation, files a chargeback, or guarantees success. Invalid or mismatched credentials and non-actionable manifests are rejected before payment; an identical settled retry with the same payment credential avoids a second settlement, while generatedAt and deadlineStatus can reflect the current time.
| Name | Type | Req | Description |
|---|---|---|---|
| access_token | string | yes | Secret bearer token returned by create_exit_manifest or deterministic settlement recovery. Required with manifest_id; treat it like a credential and do not log or expose it. |
| manifest_id | string | yes | Unguessable Exit Manifest identifier returned by create_exit_manifest. It starts with xm_ followed by 32 lowercase hexadecimal characters. |
| Name | Type | Req | Description |
|---|---|---|---|
| actionability | object | yes | Why the stored manifest is actionable and which exit route is established. |
| assessment | string | yes | Reversibility assessment preserved by the manifest. |
| currency | string | – | Currency associated with recorded monetary values. |
| deadlineStatus | string | yes | Current status of the recorded exit deadline at generation time. |
| evidenceChecklist | array | yes | Evidence to retain while pursuing the exit. |
| exitRoute | object | yes | Recorded cancellation/refund route or cited-source route to follow. |
| generatedAt | string | yes | Timestamp when the action pack was generated. |
| limitations | array | yes | Boundaries and caveats; ExitProof does not execute the exit or guarantee success. |
| manifestId | string | yes | Manifest used to build this action pack. |
| maximumStatedLossMinor | – | – | Maximum stated loss in minor currency units when established. |
| prerequisites | array | yes | Checks to complete before acting on the exit plan. |
| reversibleUntil | – | – | Recorded exit deadline when established. |
| schemaVersion | – | yes | Exit-pack response schema version. |
| sources | array | yes | Recorded source references supporting the action pack. |
| steps | array | yes | Ordered bounded next steps for pursuing cancellation or refund. |
| suggestedRequest | string | yes | Suggested message the user or agent can adapt when requesting cancellation/refund. |
| unresolvedLossExposure | boolean | – | True when the recorded evidence does not establish a complete maximum loss. |
No examples provided.
check_agent_purchase Check agent purchase ~424
Inspect one autonomous HTTP purchase before the calling agent pays it. This $0.01 machine-payment operation validates a real 402 challenge, compares advertised price/protocol/network/asset/payment destination when supplied, checks x402 v2 exact resource binding when available, and surfaces retry or settled-delivery recovery signals. ExitProof never forwards payment credentials and never sends a live POST, PUT, PATCH, or DELETE probe; for those methods the caller supplies an already-observed 402 challenge. Conflicting, malformed, inaccessible, non-402, or unsafe targets are rejected before ExitProof issues its own payment challenge. Use check_reversibility instead for cancellation/refund terms on a real-world commitment, create_exit_manifest to preserve an eligible exit path, and build_exit_pack when an exit is actually needed. A successful check is not a recommendation, merchant-identity guarantee, delivery guarantee, legal opinion, or authorization to spend.
| Name | Type | Req | Description |
|---|---|---|---|
| advertised | object | – | Optional payment facts advertised by discovery metadata. ExitProof compares these to the observed 402 challenge and rejects material conflicts before its own payment challenge. |
| live_probe | boolean | – | Whether ExitProof may make one anonymous, credential-free request to target_url. Defaults true for GET/HEAD and false for state-changing methods. |
| observed_response | object | – | A 402 response already observed by the calling agent. Required when live_probe is false. Supply payment challenge headers only, never a payment credential. |
| operation | string | – | Optional caller label for the target operation. This is descriptive only and is included in the check digest. |
| request_method | string | – | HTTP method of the contemplated purchase. Live probing is allowed only for GET or HEAD. For state-changing methods supply observed_response instead. |
| retry_contract | object | – | Optional retry, settled-delivery recovery, and refund/reversal facts advertised by the target. These remain caller-supplied unless independently verified elsewhere. |
| target_url | string | yes | Public HTTPS endpoint the agent is considering paying. Credentials, localhost, private-address literals, and non-HTTPS URLs are rejected. |
| Name | Type | Req | Description |
|---|---|---|---|
| advertised | – | – | Normalized caller-supplied advertised terms used for consistency checks. |
| assessment | string | yes | Bounded pre-payment status. This is not a recommendation to buy. |
| availablePaymentOffers | array | yes | All parseable x402 or MPP offers found in the observed response. |
| checkDigest | string | yes | SHA-256 digest of the normalized target, payment facts, recovery facts, and evidence provenance. |
| checkedAt | string | yes | Time the check result was produced. |
| checks | array | yes | Individual safety checks. Conflicts reject before payment and therefore never appear as a paid result. |
| evidence | array | yes | Evidence provenance, including whether the 402 challenge was independently observed by ExitProof. |
| limitations | array | yes | Boundaries on what the paid result establishes. |
| nextStep | object | yes | Machine-readable status and bounded instruction for the calling agent. |
| observedPayment | object | yes | Selected machine-payment offer normalized from the observed 402 challenge. |
| receiptEnvelope | – | yes | Additive Davisville Receipt Envelope v1. The native ExitProof purchase-check result remains authoritative. |
| reversibility | object | yes | Published retry, settled-delivery recovery, and reversal metadata supplied for this target. |
| schemaVersion | – | yes | Agent purchase check schema version. |
| target | object | yes | Normalized target endpoint and contemplated method. |
No examples provided.
check_reversibility Check reversibility ~548
Evaluate one commitment’s cancellation/refund reversibility from transaction-specific checkout terms plus maintained policy evidence, without charging or creating durable state. Use before a purchase, booking, subscription, rental, service, ticket, digital purchase, or deposit when exit deadlines or loss matter; use list_supported_policies only for maintained-overlay coverage, and create_exit_manifest only after paidExitManifestAvailable=true. Do not use for purchase desirability, legal advice, chargeback decisions, or executing a cancellation. Supply checkout_terms whenever available because they control the transaction-specific assessment; expected_commitment_at moves deadline evaluation forward when the commitment is future-dated, and missing or conflicting evidence can return assessment=unknown rather than inventing an exit right.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | number | yes | Commitment amount in major currency units, for example 125.50 for USD 125.50. Must be non-negative and uses currency below for all monetary interpretation. |
| checkout_terms | object | – | Transaction-specific cancellation, refund, renewal, charge, and loss terms observed for this exact commitment. Supply these whenever available; they control the transaction-specific assessment while… |
| client_reference | string | – | Optional caller-owned correlation reference. ExitProof stores only a SHA-256 hash; do not place secrets or sensitive personal data here. |
| commitment_type | string | yes | Closest category for the commitment being evaluated. This affects policy matching and should describe what the user is committing to, not the payment method. |
| country | string | – | Optional two-letter ISO 3166-1 alpha-2 country code, such as US. Used to scope maintained policy rules when geography matters. |
| currency | string | – | Three-letter ISO 4217 currency code for amount and all monetary checkout terms. Defaults to USD. |
| event_type | string | – | Lifecycle event for this commitment. Use renewal for a recurring renewal, reservation for a booking event, deposit for a deposit event, or leave omitted for an initial commitment. |
| expected_commitment_at | string | – | RFC 3339 timestamp with explicit timezone for when the commitment is expected to occur. ExitProof evaluates time windows at the later of now and this timestamp. |
| merchant | string | yes | Merchant, platform, provider, or counterparty name exactly enough to identify the commitment. Used to match maintained policy overlays; do not include account numbers, credentials, or secrets. |
| purchase_channel | string | – | Where the commitment is being made or billed. Use apple or google_play when that billing platform controls cancellation/refund rules; use direct for the merchant itself. |
| region | string | – | Optional state, province, or region label when the commitment or merchant terms are region-specific. |
| Name | Type | Req | Description |
|---|---|---|---|
| amountMinor | integer | yes | Commitment amount in minor currency units. |
| assessment | string | yes | Evidence-bounded reversibility classification. unknown means current evidence is insufficient or conflicting. |
| caseDigest | string | yes | Stable digest of the normalized commitment inputs used for this assessment. |
| commitmentType | string | yes | Normalized commitment type. |
| currency | string | yes | Normalized three-letter currency code. |
| currentExitEstablished | – | – | Whether current evidence establishes an exit route. |
| decisionSupport | object | – | Decision-support summary that does not decide whether the user should make the commitment. |
| evaluatedAt | string | yes | Timestamp at which the commitment was evaluated. |
| evidence | array | yes | Evidence items supporting or limiting the assessment. |
| evidenceBasis | string | – | Whether the assessment is based on checkout terms, maintained policy, both, or insufficient evidence. |
| evidenceConflict | boolean | – | True when evidence conflicts and cannot safely support a confident paid result. |
| evidenceState | string | – | Current evidence state, such as established, incomplete, conflicting, expired, or missing. |
| exitPackEligibility | object | – | Reasoned actionability status for a future exit pack. |
| limitations | array | yes | Important limits on what the assessment proves. |
| maximumStatedLossMinor | – | – | Maximum stated loss in minor currency units when safely established, otherwise null. |
| merchant | string | yes | Normalized merchant or platform name. |
| paidExitManifestAvailable | boolean | yes | Whether current evidence passes the preflight required before create_exit_manifest can be challenged for payment. |
| paidExitPackAvailable | boolean | yes | Whether the current evidence appears actionable enough for a later exit pack after a manifest exists. |
| reason | string | yes | Concise evidence-grounded explanation of the assessment. |
| reversibleUntil | – | – | Recorded exit deadline when established, otherwise null. |
| schemaVersion | – | yes | ExitProof reversibility result schema version. |
No examples provided.
create_exit_manifest Create Exit Manifest ~543
Persist a privacy-minimized Exit Manifest for an eligible commitment, then return its manifest_id and secret access_token. Use only after check_reversibility says paidExitManifestAvailable=true; pass the exact commitment facts to preserve, with transaction-specific checkout_terms controlling the assessment when supplied. Use check_reversibility for evaluation only, or get_exit_manifest when a manifest already exists. This state-changing $0.25 stablecoin MPP operation checks eligibility before any payment challenge; a fresh authorization creates durable state, while an identical settled retry with the same payment credential recovers the same manifest without a second settlement. The plaintext access token is returned to the caller but stored only as a SHA-256 hash.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | number | yes | Commitment amount in major currency units, for example 125.50 for USD 125.50. Must be non-negative and uses currency below for all monetary interpretation. |
| checkout_terms | object | – | Transaction-specific cancellation, refund, renewal, charge, and loss terms observed for this exact commitment. Supply these whenever available; they control the transaction-specific assessment while… |
| client_reference | string | – | Optional caller-owned correlation reference. ExitProof stores only a SHA-256 hash; do not place secrets or sensitive personal data here. |
| commitment_type | string | yes | Closest category for the commitment being evaluated. This affects policy matching and should describe what the user is committing to, not the payment method. |
| country | string | – | Optional two-letter ISO 3166-1 alpha-2 country code, such as US. Used to scope maintained policy rules when geography matters. |
| currency | string | – | Three-letter ISO 4217 currency code for amount and all monetary checkout terms. Defaults to USD. |
| event_type | string | – | Lifecycle event for this commitment. Use renewal for a recurring renewal, reservation for a booking event, deposit for a deposit event, or leave omitted for an initial commitment. |
| expected_commitment_at | string | – | RFC 3339 timestamp with explicit timezone for when the commitment is expected to occur. ExitProof evaluates time windows at the later of now and this timestamp. |
| merchant | string | yes | Merchant, platform, provider, or counterparty name exactly enough to identify the commitment. Used to match maintained policy overlays; do not include account numbers, credentials, or secrets. |
| purchase_channel | string | – | Where the commitment is being made or billed. Use apple or google_play when that billing platform controls cancellation/refund rules; use direct for the merchant itself. |
| region | string | – | Optional state, province, or region label when the commitment or merchant terms are region-specific. |
| Name | Type | Req | Description |
|---|---|---|---|
| accessToken | string | yes | Secret bearer token required with manifestId for later retrieval or exit-pack creation. ExitProof does not store this token in plaintext. |
| accessTokenReissuedForSettlementRecovery | boolean | – | True only when deterministic settlement recovery re-derived the access token after a settled delivery failure. |
| accessTokenReturnedOnce | boolean | yes | Whether this response is the first normal return of the access token. |
| assessment | string | yes | Reversibility assessment preserved in the manifest. |
| createdAt | string | yes | Manifest creation timestamp. |
| expiresAt | string | yes | Manifest expiration timestamp. |
| manifestId | string | yes | Unguessable identifier for the stored Exit Manifest. |
| paidExitPackAvailable | boolean | – | Whether the stored manifest is eligible for an exit-pack preflight at creation time. |
| privacyNote | string | yes | How ExitProof protects and may recover the access token. |
No examples provided.
get_exit_manifest Get Exit Manifest ~186
Retrieve one previously created Exit Manifest without charging or changing stored state. Pass manifest_id and access_token together: the ID selects the record and the secret token authorizes access to that same record, so neither value is sufficient alone. Use this for preserved evidence and terms; use build_exit_pack for an actionable cancellation/refund plan, or create_exit_manifest when no manifest exists. This free, repeatable read does not refresh, re-evaluate, or extend evidence; missing, expired, or mismatched credentials fail without modifying the manifest.
| Name | Type | Req | Description |
|---|---|---|---|
| access_token | string | yes | Secret bearer token returned by create_exit_manifest or deterministic settlement recovery. Required with manifest_id; treat it like a credential and do not log or expose it. |
| manifest_id | string | yes | Unguessable Exit Manifest identifier returned by create_exit_manifest. It starts with xm_ followed by 32 lowercase hexadecimal characters. |
| Name | Type | Req | Description |
|---|---|---|---|
| manifest | object | yes | Stored Exit Manifest. This read does not refresh or reinterpret the original evidence. |
| schemaVersion | – | yes | Manifest-read response schema version. |
No examples provided.
list_supported_policies List supported policies ~117
List the maintained merchant policy overlays and snapshot version/date ExitProof can add to transaction-specific evidence. Use this only to inspect maintained coverage; use check_reversibility to evaluate an actual commitment, including an unlisted merchant when transaction-specific checkout_terms are available. An absent merchant means no maintained overlay, not that no cancellation, refund, contractual, or legal right exists. This is a free read-only snapshot: it creates no durable state, issues no payment challenge, and does not fetch or verify a merchant’s live policy at call time.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| important | string | yes | Coverage caveat explaining that transaction-specific checkout terms can be used for any merchant. |
| merchants | array | yes | Merchants with maintained policy overlays. |
| policySnapshot | object | yes | Version and verification date for the maintained policy snapshot. |
| schemaVersion | – | yes | Supported-policy response schema version. |
No examples provided.
What is the ExitProof MCP server?
ExitProof is an MCP server listed in the public MCP registry as com.davisvillelabs/exitproof. Reversibility intelligence and durable exit evidence for AI agents before real-world commitments. This page covers its hosted endpoint (https://exitproof.davisvillelabs.com/mcp).
Is the ExitProof MCP server safe to use?
ExitProof scores 71 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the ExitProof MCP server expose?
ExitProof exposes 6 tools: check_reversibility, check_agent_purchase, create_exit_manifest, get_exit_manifest, build_exit_pack, list_supported_policies. Their descriptions and schemas cost roughly 2,042 tokens of context every time the server is loaded.
Does the ExitProof MCP server require authentication?
No. We connected to ExitProof without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the ExitProof MCP server still maintained?
ExitProof is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.